CEH AI Exam 2026 study guide covering exam domains, passing score, and preparation plan

How to Pass the CEH Exam on Your First Attempt in 2026

CEH AI exam domains, passing score, study timeline, and a practical preparation strategy.

Updated August 2026

Passing the Certified Ethical Hacker exam on your first attempt is possible, but no course, trainer, or study guide can guarantee the result.

The strongest approach is to understand what the current exam tests, build the necessary technical foundations, follow the official blueprint, and use practice exams to identify weaknesses before exam day.

This guide is based on the current CEH AI program, commonly associated with CEH v13, and the published CEH Exam Blueprint v5.0.

The current evolution of the Certified Ethical Hacker program is marketed by EC-Council as CEH AI. It is also commonly referred to as CEH v13 in training materials and discussions.

The knowledge-based certification exam continues to use:

  • Exam code: 312-50
  • Format: Multiple-choice questions
  • Published blueprint: CEH Exam Blueprint v5.0
  • Number of domains: Nine

Artificial intelligence is integrated across the current learning program rather than presented as a separate tenth exam domain.

Current preparation may include AI-assisted concepts related to:

  • Reconnaissance and information gathering
  • Vulnerability analysis
  • Threat detection and analysis
  • Security automation
  • Reporting
  • Defensive recommendations
  • Ethical and responsible use of AI

👉 When selecting preparation materials, confirm that they align with both the current official blueprint and the AI-enhanced direction of the CEH program.

Exam Overview

CEH knowledge Exam at a Glance

The CEH knowledge exam is different from the optional CEH Practical exam. Here is what to expect from the knowledge-based certification exam.

125 Multiple-choice questions
4 Hours Total time limit
60%–85% Published passing range
9 Exam domains
Exam detail CEH knowledge exam
Exam code
312-50
Format
Multiple-choice questions
Number of questions
125
Time limit
4 hours
Published passing range
60%–85%
Current blueprint
CEH Exam Blueprint v5.0
Main content areas
9 exam domains
Delivery
ECC Exam Portal or Pearson VUE, subject to current availability

Your Average Time per Question

Four hours for 125 questions provides approximately 1 minute and 55 seconds per question. This is an average—not a target for every individual question.

Exam strategy: answer straightforward questions efficiently. Preserve more time for difficult scenarios, marked questions, and your final review.
Know the Difference

CEH Knowledge Exam vs. CEH Practical

The standard CEH credential is earned by passing the proctored knowledge exam. The separate CEH Practical evaluates hands-on skills in a cyber range.

Knowledge-based certification

CEH Knowledge Exam

Required

The proctored multiple-choice examination required to earn the standard CEH credential.

  • 125 multiple-choice questions Knowledge-based format
  • 4 hours Total examination time
  • Tests cybersecurity knowledge Concepts, tools, methodologies, and countermeasures
  • Exam code 312-50 Official CEH knowledge exam
  • Required for the CEH credential Standard certification path
Hands-on assessment

CEH Practical

Optional

A separate practical assessment that evaluates the application of ethical hacking skills through challenges in a cyber range.

  • 20 practical challenges Performance-based format
  • 6 hours Total practical assessment time
  • Tests hands-on application Practical tools and ethical hacking techniques
  • Separate practical assessment Not part of the 312-50 knowledge exam
  • Additional exam for CEH Master Optional next certification step

Understand the Certification Path

Step 1 Pass the Knowledge Exam 312-50 · Required
Step 2 Earn the CEH Credential Standard certification
Optional next step CEH Practical → CEH Master Additional hands-on assessment
This guide focuses on the CEH AI knowledge exam. The study plan, blueprint domains, passing-score explanation, and mock-exam strategy are designed primarily for the 125-question 312-50 examination.
Official Exam Blueprint

CEH Exam Domains and Topics

The CEH Exam Blueprint v5.0 organizes the knowledge exam into nine domains. Their published weightings indicate how much of the exam each content area represents.

01 6%

Information Security and Ethical Hacking Overview

Ethical hacking concepts, controls, methodologies, laws, and information security standards.

Exam weight 6%
02 17%
High priority

Reconnaissance Techniques

Footprinting, scanning, host discovery, service discovery, operating-system discovery, and enumeration.

Exam weight 17%
03 15%
High priority

System Hacking Phases and Attack Techniques

Vulnerability analysis, gaining access, privilege escalation, persistence, malware, and countermeasures.

Exam weight 15%
04 24%
Highest weight

Network and Perimeter Hacking

Sniffing, social engineering, denial-of-service, session hijacking, IDS, firewalls, honeypots, and evasion.

Exam weight 24%
05 14%
High priority

Web Application Hacking

Web servers, applications, APIs, authentication, authorization, access control, and SQL injection.

Exam weight 14%
06 5%

Wireless Network Hacking

Wireless concepts, encryption, threats, Bluetooth, tools, attack techniques, and countermeasures.

Exam weight 5%
07 10%

Mobile Platform, IoT, and OT Hacking

Mobile attack vectors, Android, iOS, IoT, operational technology, attack methodologies, and defenses.

Exam weight 10%
08 5%

Cloud Computing

Cloud concepts, containers, serverless computing, threats, attack techniques, and cloud security.

Exam weight 5%
09 5%

Cryptography

Encryption, hashing, PKI, digital certificates, cryptanalysis, attacks, and countermeasures.

Exam weight 5%
Study priorities

Where Should You Spend the Most Time?

The four largest domains should receive the greatest share of your study time.

1 Network and Perimeter Hacking
24%
2 Reconnaissance Techniques
17%
3 System Hacking Phases and Attack Techniques
15%
4 Web Application Hacking
14%
Together, these four domains represent 70% of the published exam blueprint. Your study schedule should reflect their combined weight.
Do not ignore the smaller domains. Wireless security, cloud computing, and cryptography may each represent only 5%, but those questions can still affect your final result—especially when the applicable cut score is toward the upper end of the published range.

Use a Balanced Study Strategy

Spend more time on the highest-weight domains.
Build minimum competence in every exam domain.
Use practice-test results to adjust your schedule.
Revisit weak areas even when their weighting is lower.
Confirm that your materials cover the current AI-enhanced CEH program.

There is no single preparation timeline that works for every candidate.

The time you need depends on:

  • Your current cybersecurity knowledge
  • Your professional experience
  • Your familiarity with Linux and Windows
  • Your understanding of networking and web technologies
  • The number of hours you can study each week
  • Your performance on practice exams

Allow approximately 6–8 weeks of structured preparation.

You may already understand networking, operating systems, vulnerabilities, and security controls. However, you still need to study the terminology, tools, methodologies, and scope used by the CEH blueprint.

Allow approximately 8–12 weeks.

Spend additional time on reconnaissance, system hacking, web security, malware, security tools, and attack countermeasures.

Allow approximately 12–16 weeks or longer.

Before intensive exam preparation, build foundations in:

  • Networking and common protocols
  • Windows and Linux
  • Users, permissions, and authentication
  • Web technologies
  • Security threats and vulnerabilities
  • Basic command-line usage
  • Ethical and legal security testing

These timelines are planning estimates—not official requirements or guarantees. Your readiness should be determined by understanding and mock-exam performance, not only by the number of weeks you have studied.

Eight-Step Preparation Strategy

A Practical CEH AI Study Plan

Build your preparation around the official blueprint, strengthen weak foundations, and use practice results to decide when you are ready.

Establish the scope

Begin With the Official Blueprint

Download the current exam blueprint before choosing books, videos, courses, or question banks. Use it as a checklist throughout your preparation.

View the Official Blueprint

For every domain, identify:

  • Concepts you understand
  • Topics you recognize but cannot explain
  • Topics that are completely new
  • Tools and commands you need to recognize
  • Attacks and their associated countermeasures
  • AI-enhanced workflows relevant to the subject

Do not assume that a resource is current simply because it includes “CEH” in its title. Look for explicit alignment with CEH AI, CEH v13, and Exam Blueprint v5.0.

CEH Tip

Create a red, amber, and green status for every blueprint topic: green means you can explain it, amber means partial understanding, and red means it needs structured study.

Check your readiness

Assess Your Foundations Honestly

CEH preparation becomes harder when you are simultaneously learning basic networking, Linux, web technology, and ethical hacking terminology.

Check whether you can explain:

  • The TCP/IP and OSI models
  • Common ports and protocols
  • IP addresses, subnets, DNS, and DHCP
  • Linux files, permissions, processes, and commands
  • Windows users, services, and authentication
  • The difference between a threat, vulnerability, and exploit
  • Web requests, responses, sessions, and cookies
  • Encryption, hashing, and digital signatures
  • Vulnerability assessments and penetration tests

If several areas are unfamiliar, strengthen your foundations before relying heavily on practice questions.

CEH Tip

Try explaining each foundation aloud without notes. If you cannot describe it simply or give an example, mark it for review before moving to advanced tools.

Build a schedule

Study by Domain, Not Randomly

Avoid jumping between unrelated videos, tools, and question banks. Organize your preparation around the nine official domains.

Weeks Primary focus
1–2 Foundations, ethical hacking overview, and responsible AI use
3–4 Reconnaissance, scanning, and enumeration
5–6 Vulnerability analysis, system hacking, and malware
7–8 Network and perimeter hacking
9 Web servers, applications, APIs, and SQL injection
10 Wireless, mobile, IoT, and OT
11 Cloud computing and cryptography
12 Timed mock exams and targeted review

Adjust this schedule based on your experience and practice-test results.

CEH Tip

Give the four largest domains more study time, but schedule a short weekly review of wireless, cloud, and cryptography so the smaller domains are not forgotten.

Learn the workflow

Understand What the Tools Are Doing

The exam may require you to recognize tools, outputs, options, attack techniques, and countermeasures.

Nmap Wireshark Burp Suite Metasploit theHarvester Nikto SQLmap John the Ripper Hashcat Aircrack-ng

For each important tool, understand:

  1. Its primary purpose
  2. The ethical hacking phase in which it is used
  3. The type of information it produces
  4. Common commands or options
  5. Limitations and potential false positives
  6. Relevant detection or prevention measures
  7. When its use requires explicit authorization
  8. How AI may assist analysis without replacing validation
CEH Tip

Create one study card per tool with four fields: purpose, input, output, and countermeasure. This is more effective than memorizing isolated tool names.

Reinforce understanding

Use Authorized Labs

The knowledge exam is multiple choice, but practical exercises make technical concepts easier to understand and remember.

Use only:

  • Systems you own
  • Dedicated virtual machines
  • Authorized cybersecurity training platforms
  • Environments for which you have explicit permission

After each exercise, document:

  • What you were trying to discover
  • Which tool or technique you used
  • What the output meant
  • Which vulnerability or weakness was involved
  • Which security controls could detect or prevent it
  • How you validated any AI-assisted analysis
CEH Tip

Create a clean VM snapshot before each major exercise. After the lab, save one screenshot and a short explanation of the attack and its countermeasure.

Only practice against systems and environments you own or are explicitly authorized to test.
Use AI responsibly

Use AI as a Study Assistant

AI can help you:

  • Simplify difficult concepts
  • Compare related attacks
  • Create revision questions
  • Organize a study schedule
  • Explain command output
  • Review your notes
  • Improve the structure of a lab report

AI can also produce incomplete, outdated, or incorrect information. Validate important facts against:

  • The official EC-Council blueprint
  • Current EC-Council documentation
  • Trusted technical documentation
  • Results observed in an authorized lab
Explain the difference between active and passive reconnaissance. Give me one example of each, explain the legal considerations, and ask me five questions to test my understanding.
CEH Tip

Ask AI to explain why an answer is correct and why the alternatives are wrong. Then verify commands, exam facts, and technical details with an official or trusted source.

Do not use AI to bypass learning, obtain prohibited exam content, or perform unauthorized security testing.
Diagnose weak areas

Use Practice Questions Correctly

Practice questions should diagnose your understanding—not replace it.

Classify every mistake as a:

  • Knowledge gap
  • Misread question
  • Confused term or methodology
  • Forgotten command or tool
  • Weak understanding of the countermeasure
  • Time-management problem
  • Overreliance on an automated explanation

Review the underlying topic before attempting similar questions again.

CEH Tip

Maintain an error log with the question topic, your incorrect reasoning, the correct explanation, and the blueprint domain. Review this log every week.

Avoid brain dumps and websites claiming to provide “real exam questions.” They may be inaccurate, outdated, unethical, or prohibited by certification rules.
Simulate the exam

Complete Full Timed Mock Exams

Short quizzes do not reproduce the concentration required for a four-hour examination.

Complete multiple fresh mock exams with:

  • 125 questions
  • A four-hour maximum
  • No notes
  • No interruptions
  • No immediate answer checking
  • A final review before submission

Track performance by domain—not only by total score. A strong overall result can hide a repeated weakness in reconnaissance, networking, or another important area.

CEH Tip

Do not schedule the exam based on one strong result. Look for consistent performance across several fresh mock exams and stable results in every major domain.

Repeating the same mock exam until you memorize its answers measures memory—not exam readiness.
Use evidence to decide when you are ready. Blueprint coverage, domain-level results, technical understanding, and consistent performance are more reliable than the number of weeks you have studied.

Knowledge alone won’t help if you panic during the exam.

  • Stay calm and manage stress (deep breathing, hydration, rest)
  • Read carefully — EC-Council loves “trick wording”
  • Manage time — aim for ~2 minutes per question

👉 Analogy: The exam is like a chess game — patience and strategy beat rushing.

CEH Tip: Don’t second-guess yourself too much. Often, your first instinct is correct.

  • 📌 Know the exam format & domains before starting
  • 📌 Build strong foundations in networking, OS, and tools
  • 📌 Study consistently with a structured plan
  • 📌 Use mock exams, and cheat sheets for reinforcement
  • 📌 On exam day: stay calm, manage time, and trust your prep
  • 📌 CEH is a stepping stone to bigger certifications and career growth
Ready for a Clearer Study Path?

Stop Guessing What to Study for CEH AI

Replace disconnected videos, outdated guides, and random question banks with one structured path through the complete CEH AI v13 scope.

Back2Skills CEH® AI v13 Program

Turn the CEH Blueprint Into a Clear Learning Path

Build the understanding behind the tools, techniques, AI workflows, and countermeasures—then test your readiness with structured quizzes and two complete mock exams.

  • 20 structured CEH AI v13 modules
  • AI-enhanced cybersecurity concepts
  • Visual cheat sheets and module quizzes
  • Lab Focus guidance for practical learning
  • Two complete 125-question mock exams
  • Lifetime access with no subscription

Completely New to Ethical Hacking?

Build your foundations first with Ethical Hacking, Linux, and Penetration Testing in one structured 3-course path.

Explore the Foundations Bundle

Understand first. Practice next.

Practice legally and responsibly. All ethical hacking techniques must only be used with explicit authorization and in legal practice environments.